ExamGecko
Question list
Search
Search

Related questions

Question 185 - CISA discussion

Report
Export

Which of the following is the BEST source of information tor an IS auditor to use when determining whether an organization's information security policy is adequate?

A.
Information security program plans
Answers
A.
Information security program plans
B.
Penetration test results
Answers
B.
Penetration test results
C.
Risk assessment results
Answers
C.
Risk assessment results
D.
Industry benchmarks
Answers
D.
Industry benchmarks
Suggested answer: C

Explanation:

The best source of information for an IS auditor to use when determining whether an organization's information security policy is adequate is the risk assessment results. The risk assessment results provide the auditor with an overview of the organization's risk profile, including the identification, analysis, and evaluation of the risks that affect the confidentiality, integrity, and availability of the information assets. The auditor can use the risk assessment results to compare the organization's information security policy with the risk appetite, risk tolerance, and risk treatment strategies of the organization. The auditor can also use the risk assessment results to evaluate if the information security policy is aligned with the organization's objectives, requirements, and regulations.

Some of the web sources that support this answer are:

Performance Measurement Guide for Information Security

ISO 27001 Annex A.5 - Information Security Policies

[CISA Certified Information Systems Auditor -- Question0551]

asked 18/09/2024
Vojtech Danek
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first